AMD Processors Improper Access Control Vulnerability Allowing Physical Access Attacks
Vulnerability
A vulnerability exists in AMD Ryzen and Ryzen Embedded series processors due to improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI). This flaw could enable an attacker with physical access to read or overwrite the contents of cross-chip debug registers, potentially compromising data integrity or confidentiality.
Impact
Exploitation of this vulnerability could lead to unauthorized access to debug registers, allowing for manipulation of data integrity or confidentiality.
Remediation
Users are advised to update to the Platform Initialization (PI) firmware version PhoenixPI-FP8-FP7_1.2.0.B, released on March 12, 2025. For AMD Ryzen Embedded processors, the recommended update is to version EmbeddedPhoenixPI-FP7r2_1.0.0.2, available since June 18, 2025.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
